Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
3711 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 0.49% | — | Oracle Webcenter Content | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While… | |
| Modificada | Media (5.7) | 0.15% | — | Powerschool Employee Access Center | 16/6/2026 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access Center allows Cross-Site Scripting (XSS). This issue affects Employee Access Center: 23.10. It is possible to add in javascript code after the login URL and have it be eval()'d in… | |
| Pendiente de análisis | Alta (8.8) | 0.45% | — | Dell Openmanage Integration FOR Microsoft Windows Admin CenterAIMicrosoft Windows Admin CenterAI | 16/6/2026 | 1/10/2026 | Dell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vulnerability in the gateway plugin. A remote authenticated user could potentially exploit this vulnerability to escalate privileges. The malicious user may gain the ability to run arbitrary code remotely. This is a high… | |
| Modificada | Media (4.6) | 0.26% | — | Qnap License Center | 10/6/2026 | 23/7/2026 | A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: License Center 1.9.56 and… | |
| Analizada | Media (5.1) | 0.16% | — | Qnap Notification Center | 10/6/2026 | 5/8/2026 | A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: Notification Center 1.10.0.3291 and later | |
| Analizada | Alta (7.1) | 0.39% | — | Schneider-electric Struxureware Data Center Expert | 9/6/2026 | 20/7/2026 | CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints. | |
| Pendiente de análisis | Alta (7.8) | 0.15% | — | Genetec Security CenterAI | 2/6/2026 | 22/7/2026 | A high security vulnerability affecting Security Center main server installations has been identified. It could allow an attacker with local OS privileges to the main server to access the Server Admin credentials. A third party hired by Genetec found the issue. There is currently no evidence of active exploitation.… | |
| Aplazada | Alta (7.1) | 0.43% | — | HP Service CenterAI | 29/5/2026 | 21/7/2026 | Service Center developed by BankPro E-Service Technology has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify the parameter of a specific query function to access other users' EC order details. | |
| Aplazada | Media (4.6) | 0.20% | — | Hitachi OPS Center AnalyzerAIHitachi OPS Center Analyzer ViewpointAIHitachi Infrastructure Analytics AdvisorAI | 26/5/2026 | 24/7/2026 | Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe modules), Hitachi Ops Center Analyzer viewpoint, Hitachi Infrastructure Analytics Advisor (Data Center Analytics, Analytics probe modules). This issue affects Hitachi… | |
| Analizada | Media (6.8) | 0.12% | 💥 PoC | Acer Care Center | 25/5/2026 | 23/7/2026 | A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a weak Security Descriptor. This vulnerability allows an authenticated local user to connect and send a specially crafted message (message type 0x03) to the pipe, causing the service to crash with exit… | |
| Modificada | Alta (7.8) | 0.37% | — | Microsoft Windows Admin Center | 20/5/2026 | 23/7/2026 | Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (8.2) | 0.28% | — | Talend Administration CenterAI | 20/5/2026 | 23/7/2026 | A broken access control issue has been identified in the Talend Administration Center, that allows a user with “View” permission to modify the Talend Studio update URL. This issue was resolved in a patch, which is already available. | |
| Aplazada | Media (5.4) | 0.23% | — | Talend Administration CenterAI | 20/5/2026 | 23/7/2026 | A stored cross-site scripting vulnerability has been found in the Talend Administration Center. An attacker with permission to manage servers can store a XSS payload that can be triggered by a different user. | |
| Pendiente de análisis | Alta (7) | 0.22% | — | Powersystem CenterAI | 12/5/2026 | 17/6/2026 | PowerSYSTEM Center feature for device project groups allows an authenticated user with limited permissions to perform an unauthorized deletion of project groups. | |
| Pendiente de análisis | Media (6.9) | 0.22% | — | Powersystem CenterAI | 12/5/2026 | 17/6/2026 | PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normally limited by operational permissions. | |
| Pendiente de análisis | Alta (8.4) | 0.21% | — | Powersystem CenterAI | 12/5/2026 | 17/6/2026 | PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally restricted to administrative permissions only. | |
| Pendiente de análisis | Media (5.1) | 0.31% | — | Powersystem CenterAI | 12/5/2026 | 17/6/2026 | PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communication. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Windows Admin Center | 12/5/2026 | 17/6/2026 | Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.3) | 0.63% | — | Microsoft Windows Admin Center | 12/5/2026 | 17/6/2026 | Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | |
| Pendiente de análisis | Alta (8.3) | 0.12% | — | Intel Data Center Graphics DriverAIVmware EsxiAI | 12/5/2026 | 17/6/2026 | Out-of-bounds write for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data corruption. This result may potentially… | |
| Pendiente de análisis | Crítica (9.3) | 0.13% | — | Intel Data Center Graphics DriverAIVmware EsxiAI | 12/5/2026 | 17/6/2026 | Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable local code execution. This result may… | |
| Pendiente de análisis | Alta (8.3) | 0.12% | — | Intel Data Center Graphics DriverAIVmware EsxiAI | 12/5/2026 | 17/6/2026 | Out-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur… | |
| Pendiente de análisis | Alta (7.3) | 0.20% | — | Siemens Simcenter FemapAI | 12/5/2026 | 7/10/2026 | Siemens Simcenter Femap contains a memory corruption vulnerability while parsing specially crafted IPT files. This could allow an attacker to execute code in the context of the current process. | |
| Analizada | Alta (8.7) | 0.39% | — | Siemens Teamcenter | 12/5/2026 | 17/6/2026 | A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (All versions < V2412.0009), Teamcenter V2506 (All versions < V2506.0005), Teamcenter V2512 (All versions). The affected application contains hardcoded key which is used… | |
| Analizada | Alta (8.5) | 0.28% | — | Siemens Teamcenter | 12/5/2026 | 17/6/2026 | A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (All versions < V2412.0009), Teamcenter V2506 (All versions < V2506.0005), Teamcenter V2512 (All versions). The affected application does not properly encode or filter… |